Skip to main content

Kubernetes

In this section, you will find a list of the rules associated with the Kubernetes language and the security requirements.

MethodSecurity Requirement
K8S_CHECK_ADD_CAPABILITY095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
K8S_CHECK_DROP_CAPABILITY095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
K8S_CHECK_HOST_PID095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
K8S_CHECK_IF_CAPABILITY_EXISTS095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
K8S_CHECK_IF_SYS_ADMIN_EXISTS095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
K8S_CHECK_PRIVILEGED_USED095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
K8S_CHECK_RUN_AS_USER095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
K8S_CHECK_SECCOMP_PROFILE095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
K8S_CONTAINER_WITHOUT_SECURITYCONTEXT095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
K8S_IMAGE_HAS_DIGEST266. Disable insecure functionalities
K8S_PRIVILEGE_ESCALATION_ENABLED095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
K8S_ROOT_CONTAINER095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
K8S_ROOT_FILESYSTEM_READ_ONLY095. Define users with privileges
096. Set user's required privileges
186. Use the principle of least privilege
KUBERNETES_INSECURE_PORT181. Transmit data using secure protocols
KUBERNETES_USES_HTTP181. Transmit data using secure protocols
KUBERNETES_USES_HTTP_SERVER181. Transmit data using secure protocols